Audit findings 6.1-6.4 + the audit's remediation plan itself
(docs/superpowers/plans/2026-07-20-full-audit-remediation-plan.md).
- ruff: 34 → 0 (unused imports/f-strings auto-fixed; E702 semicolon lines
split in test files; one unused local dropped). Suite still 819 green.
- CLAUDE.md + PROJECT_STATE.md no longer claim "no database / settings in
settings.json": the harness selects filesystem OR PostgreSQL session
storage (repository.py, server mode), and settings flow through harness
preferences with the JSON file as fallback only.
- tools/replay: stub /me (SPA boot was parsing the SPA's own HTML as JSON)
and /runtime/prewarm.
- failSession best-effort persistence now logs its failure server-side
instead of vanishing.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
Bite-sized TDD tasks: schema-linking types + columns modal, gate widget with
staged per-table column selection, registry/summary wiring, and a replay
fixture generated from the real physical.yaml catalog. Offline-verifiable in
the replay server; harness wiring is Plan 2.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Reviewer curates, per promoted table, which columns to use over the full
catalog list (suggested pre-selected + bold); selection persists into
schema_linking.json + the decision ledger and softly guides SQL generation
(Option 1). Dedicated structured schema-linking gate widget (Approach A),
staged commit, inline gate + single columns modal. Hard SQL enforcement is
an explicit follow-up.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- present() = presentBlockingWidget: transport + no-limbo loop + response
validation; both branches share validateUiResponse; the id invariant must be
validated explicitly in the TUI branch (emitAndWait no longer runs there)
- TUI renderer uses numbered options + index parsing, never label mapping
(frontend already answers with ids); artifact-gate editor is viewer-only,
returned content ignored
- guards resolved: both TUI-only notices now ctx.mode === "tui"
- interactive-render.js as two layers (renderTuiDescriptor +
validateSyntheticResponse); add negative test cases + a real TUI smoke
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- #1 hasUI: real 0.80.3 comment is "true in TUI and RPC modes" (doc had the old
0.73.1 "false in print/RPC"). hasUI no longer distinguishes TUI from RPC, so it
is NOT a fallback for the interactive branch — only ctx.mode === "tui" is.
- #2 info/freetext: buildInfoRequest exists in builders.js but is NOT wired into
tht-gate.js (imports only select/multiselect/artifact-gate). info notices are
hand-written ctx.ui.notify; freetext is a control, not a descriptor. Table now
lists only the 3 real present() descriptors.
- #3 cite the REWRITE banner (tht-gate.js:8-10), not :227; id-match quoted verbatim.
- #4 new "Note implementative": 227 comment, 4/6 unguarded notify, and the
ctx.hasUI guard migration side-effect (now fires in RPC on 0.80.3).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>